02-347-7730  |  Saeree ERP - Complete ERP Solution for Thai Organizations Contact Us

Data Leaks from Excel Files

A laptop showing financial data left open on a desk in an empty office — the risk of leaking data by sharing Excel files
  • 19
  • February

In many organizations, Excel files are no longer just a calculation tool — they have become the place where the company's real data lives, from payroll and cost prices to customer registers. And the channels through which that data escapes are mostly not break-ins. They are ordinary daily work: attaching a file to an approval email, forwarding it to a colleague for a second opinion, copying it onto a USB drive to finish at home — and, new in 2026, uploading the file to an AI tool using a personal account to have it summarized or to get a formula written.

Last updated 3 September 2026 — added 2026 security-report data, Thai PDPA enforcement cases, and a seven-day action plan.

In short: the risk in an Excel file is not the software — it is that the file travels on its own. Once a copy leaves the owner's hands, the organization cannot tell where it went, cannot revoke access, and cannot answer how much data about whom was exposed. That last question is exactly what Thailand's PDPA requires a data controller to answer within 72 hours of becoming aware of a breach.

The 2025–2026 Numbers That Change the Picture

Passing Excel files around used to be treated as an internal housekeeping issue. The latest security reports put a price on it — and show that people inside the organization are a decisive variable:

Figure What it means Source
USD 4.99M Average cost of a single data breach — up 12% year over year and the highest on record IBM Cost of a Data Breach 2026
43% Share of breached organizations where shadow AI (unapproved AI use) was involved — up from 20% a year earlier, with average costs rising from USD 4.63M to USD 5.39M IBM Cost of a Data Breach 2026
92% Organizations that suffered an AI-related incident and were found to lack adequate AI access controls — the cost driver is ungoverned use, not the technology IBM Cost of a Data Breach 2026
45% / 67% 45% of employees are now regular AI users on corporate devices (up from 15%), and 67% reach AI services through non-corporate accounts Verizon DBIR 2026
12% Breaches involving internal actors (down from 18%), where the leading motive for insider misuse is convenience, at 60%, ahead of financial gain at 33% Verizon DBIR 2026
THB 21.5M Cumulative administrative fines imposed by Thailand's PDPC on both public agencies and private companies (as of fiscal year 2025) PDPC four-year results (July 2026)

The Verizon figures come from more than 31,000 analysed incidents and roughly 22,000 confirmed breaches across 145 countries. The line worth reading twice is the motive: convenience outranks financial gain. Most people who cause a leak never intended one — they simply took the fastest route to finishing the job, and that route is often "just send it as an Excel file".

Seven Ways an Excel File Leaves the Organization

All seven happen inside normal daily work. None of them requires an attacker:

Channel When it happens What leaves with the file
1. Email sent to the wrong person Autocomplete fills in a similar name and Send is pressed too quickly The whole file, not only the rows that concern the recipient
2. "Can you take a look?" forwarding One or two hops after the first send, by someone who never opened every sheet Every attachment in the thread, plus the conversation above it
3. Hidden sheets and unshown data Sending only the "summary tab" to an outsider while the file still carries the source data Hidden sheets, hidden rows and columns, active filters, and the PivotTable cache
4. "Anyone with the link" sharing Sharing with several people at once and picking the broadest option to save time Open access for everyone the link is passed to, including people outside the company
5. USB drives and personal devices Taking work home, or handing over duties before leaving the company A copy that sits permanently outside the organization's control
6. Files sent to third parties Period close, external audit, or work handed to consultants and contractors Data moves into someone else's systems, under controls you cannot inspect
7. Uploads to AI tools Wanting a summary, a clean table, or a formula — using a personal account because it is faster The file lands in an account the organization cannot audit or order deleted

A payroll file sent to the wrong person cannot be recalled

HR prepares a company-wide payroll summary for executive approval, autocomplete offers a similar-looking address, and a file containing every employee's salary reaches someone who should never have seen it. What makes this unfixable is simple: recalling an email does not unsee what the recipient already saw. One screenshot is enough for the data to keep travelling, and the organization will never know how far.

"Not displayed" is not the same as "not sent"

A single Excel file holds far more than what appears on screen. Hidden sheets, filtered-out rows, hidden columns and the PivotTable data cache all travel with the file. Sending the "summary tab" to an outsider can therefore mean sending the entire source dataset without realizing it.

Case study: one hidden tab, a GBP 750,000 fine

In August 2023 the Police Service of Northern Ireland answered a freedom-of-information request with a spreadsheet. Nobody noticed the hidden tab inside it, which contained the surnames, initials, ranks and roles of all 9,483 officers and staff. The file was online for only 2 hours and 20 minutes, but the harm could not be undone. In October 2024 the UK's ICO issued a penalty: the calculated amount was GBP 5.6 million, reduced to GBP 750,000 under its revised public-sector enforcement approach — and the regulator noted the breach could have been prevented by simple checks before publishing the file.

When the same file exists in several versions

The side effect of passing files around is that nobody can say which copy is authoritative. That shows up most sharply in work that depends on current numbers, such as tracking budget consumption during the year — a problem we covered separately in Budget Exhausted Before Year End — Why Tracking Budget with Excel Does Not Work. From a security standpoint, every additional copy is one more place the data can leak from.

The channel that appeared in the last two years: AI uploads

When an employee uploads a cost file or a customer register to an AI tool using a personal account, the organization has neither a record of what was uploaded nor any right to have it deleted. The Verizon DBIR 2026 ranks shadow AI as the third most common non-malicious insider data-loss event, roughly a fourfold increase in a single year. The answer is not "ban AI" — it is to specify which tools are allowed, which account must be used, and which categories of data may never be uploaded. We wrote about this in detail in Shadow AI — The Silent Risk IT Cannot See, and about the specific case of auditors asking for files to run through AI in Auditors Feeding Your Excel Data to AI: Is It a Data Leak?

Excel Protection Comes in Three Levels — and They Are Not Equal

"I password-protected it" can mean three very different things in practice, with very different strength:

Level What it does How much it actually protects
Password to Open Encrypts the file contents; without the password the file cannot be read at all Real encryption — strong enough if the password is long and is not sent together with the file
Password to Modify The file opens for reading but cannot be saved over without the password Prevents accidental edits; does nothing against reading, copying or forwarding
Protect Sheet / Workbook structure Locks cells against editing, or blocks adding, deleting and hiding sheets Microsoft states in its own documentation that worksheet-level protection is not intended as a security feature — it only stops edits to locked cells

What file encryption still cannot fix

Even with a genuine open-password encrypting the file, three problems remain. First, the password is usually sent in the same email or chat as the file — locking the door and hanging the key on the handle. Second, access cannot be revoked after the fact: the recipient opens it once and saves an unprotected copy. Third, there is no record of who opened it and when, so the organization still cannot answer the question that matters most during an incident — whose data was exposed, and how much of it.

PDPA: An Excel File With Personal Data Carries Legal Duties

Employee registers, payroll files and customer lists are all personal data under Thailand's Personal Data Protection Act B.E. 2562 (2019), and HR files frequently carry sensitive data as well — health records, disability information, or biometric data used for time attendance. Three duties follow:

  • Maintain appropriate security measures — and be able to demonstrate they exist in practice, not only in a policy document
  • Notify the PDPC without delay and within 72 hours of becoming aware of a breach, and notify the data subjects as well where there is a high risk to their rights and freedoms
  • Bear liability proportionate to the harm — administrative fines of up to THB 5 million, criminal penalties for certain offences, and civil liability where a court may award punitive damages on top

The second duty is the one that file sharing makes hardest to meet, because a notification has to state the scope of the harm — which categories of data, how many people — while a file that has already spread leaves no record of where it travelled. Data subject access requests are equally hard to answer when one person's data sits across dozens of files; see PDPA Data Subject Access Requests 2026 for the deadlines involved.

Penalties the PDPC has actually imposed in Thailand

On 1 August 2025 the PDPC announced THB 14.5 million in administrative fines in one round, pushing the cumulative total past THB 21 million. The notable cases and the reasons behind them:

Type of organization Fine Why it was fined
IT retailer THB 7 million Customer data used in fraudulent operations; failed to appoint a Data Protection Officer, did not report the breach, and had inadequate security safeguards
Cosmetics company THB 2.5 million Leaked data exploited by scam operations, with compliance shortcomings of the same kind
Data processor
(online reservation system)
THB 3 million
controller: THB 500,000
System breached, affecting some 200,000 records, and the processor failed to notify the controller or remediate promptly
Private hospital More than THB 1.2 million Patient records mishandled during document disposal, insufficient supervision of the contractor, and late reporting
Government agency + software developer Over THB 150,000 each A cyberattack exposed roughly 200,000 records, with weak security measures, poor password management, no risk assessments, and no data processing agreement in place

What matters in this table is how similar the reasons are. Almost none of them turn on attack sophistication: the recurring findings are measures that could not be demonstrated, breaches not reported on time, and contractors not properly supervised. Those are precisely the three things a culture of passing Excel files around makes hardest to prove. On the other side, the PDPC reports that its Eagle Eye monitoring has scanned around 900,000 URLs and resolved more than 7,000 exposure cases before damage occurred — meaning the chance that a leaked file gets noticed keeps rising.

Side by Side: Shared Files vs Data in a Central System

Excel was never designed to serve as an organization's master register. The real difference is not the feature list — it is whether the organization still controls the data after it has been sent out:

Question Shared Excel files Data in a central system (ERP)
Who can see the data Whoever holds the file sees all of it Read/write rights per user and role; users see only what they are entitled to
When someone changes role or leaves Nothing to revoke — the copy is already theirs Disable the account or withdraw the role and access ends immediately
Number of copies Every send creates another untracked copy One dataset that everyone reads from the same place
Getting data out Attach to an email or copy to a USB drive instantly Through screens and reports whose access is defined per role
Masking part of the data Only deletion or hiding — which still ships inside the file Configure fields to display as *** for users without the right to see values
Answering questions during an incident Hard to scope whose data was exposed, and how much Scope can be established from the data model and the rights granted

How Saeree ERP Shortens the File-Sharing Loop

Our approach is not to ban Excel. It is to move the most sensitive data out of the file-sharing loop so that the people who need it read it from the system under their own rights. What Saeree ERP supports here:

  • Read/write rights per user and role across each sub-system — budgeting, procurement, accounting, finance — defining who reaches which menu and which transactions
  • SSO and LDAP/AD support — when an employee leaves and the account is disabled in AD, access to the data ends with it; there are no files to chase
  • Field masking that displays values as *** through the Application Dictionary for users who should not see the real figures
  • Two-factor authentication and SSL Grade A+ — the reasoning behind requiring 2FA on business systems is in What Is 2FA? Why ERP Systems Must Have Two-Factor Authentication
  • In-system approval workflow — approvers open the record in the system under their rights instead of receiving a summary file by email, which is where files start travelling
  • Deployment on the organization's own servers, whether on-premise or on cloud accounts the customer owns — we do not host customer data on our side, so the data stays inside a perimeter the organization controls and can audit itself

Requirements worth writing into your procurement

Whichever vendor you buy from, put these six points in the requirements and test them before acceptance rather than assessing them from a brochure:

  • Role-based rights and field-level masking — test by logging in with an account that lacks the right
  • Records of data changes and data access: how far back they are retained, and how they are retrieved
  • Control over exporting data to files: who may export, and whether exports are logged
  • Encryption in transit and at rest, and at which layer it is applied (application, database or disk)
  • Support for the 72-hour breach notification — how quickly the vendor can help scope the affected data
  • A data processing agreement and confidentiality terms covering cases where the support team needs access to live data

A Seven-Day Plan That Does Not Wait for a Big Project

Reducing Excel-file risk can start immediately, without replacing any system:

Day What to do What you get
Day 1 Find where the sensitive files are: search shared drives and team mailboxes for terms like salary, payroll, cost and customer list The real scope, before deciding what to fix first
Day 2 Turn off "anyone with the link" sharing and review who still has access to folders shared long ago The widest channel closed in a single day
Day 3 Adopt three simple classification levels — public, internal, restricted — and put the level in the file name Anyone about to send a file knows instantly whether they may
Day 4 Set an export rule: restricted files are never sent as attachments, only as links addressed to named recipients with an expiry date Untrackable copies become revocable access
Day 5 Publish an AI usage policy: which tools are approved, that corporate accounts must be used, and which data may never be uploaded Shadow AI shrinks without banning AI outright
Day 6 Rehearse the 72-hour notification: who receives the internal report, who scopes it, who signs the PDPC notification, and on which form On the real day, no time lost working out who is responsible
Day 7 Pick the single most sensitive dataset — payroll, for instance — and plan its move into a central system, ending the file loop for that dataset first One dataset genuinely fixed, as the template for the next

Where Excel Still Fits, and Where It Should Not

Still a good fit for Excel Should not live in Excel
Ad-hoc analysis of data already extracted from a system Master registers: employees, customers, vendors, assets
Calculation models and scenario testing Individual salary and benefits data
Aggregated figures that cannot identify an individual Cost prices and per-vendor pricing terms
Drafting report layouts before commissioning them in the system Data that must be auditable, or that carries accounting and contractual consequences

A one-line test you can apply today

If leaking that dataset would trigger a PDPC notification or harm someone, keep it in a system where access can be granted and revoked. If leaking it would harm no one, Excel is still the best and fastest tool for the job.

Conclusion

Data leaks from Excel files are not a story about people breaking rules, nor a flaw in the software. They are the result of using a tool built for calculation and analysis to do the job of a controlled master register. Once a copy leaves the owner's hands, the organization cannot revoke access, cannot tell where the file went, and cannot answer within 72 hours what the law requires it to answer — which is exactly the pattern behind the cases the PDPC has fined.

The fix does not have to begin with a large project. Close the sharing links that are broader than they need to be, classify what you hold, set a boundary around AI tools, then pick the single most sensitive dataset and move it into a central system first. For the wider security picture at executive level, continue with Data Security in ERP Systems — What Executives Must Know.

"Data still inside the system can have its access revoked. Data that has left as a file can only be asked for back."

— The Saeree ERP Team

References

Interested in ERP for your organization?

Consult with our expert team at Grand Linux Solution

Request More Information

Call 02-347-7730 | sale@grandlinux.com

Saeree ERP Team

About the Author

Paitoon Butri

Network & Server Security Specialist, Grand Linux Solution Co., Ltd.